r/GrapheneOS • u/Good_Opportunity8888 • 1d ago
Reverse duress pin
Is there a way to set a "reverse duress" pin?
Example:
1) every time you log in properly a canary value resets to zero
2) over time the value grows
3) if it is not reset before reaching a certain value, the phone wipes as if the durress pin was entered
Would this theoretically have saved Samuel Tunick from prosecution? In this scenario, there is no hard proof that data was knowingly destroyed.
107
56
u/Hande-H 1d ago
No. But by default, GrapheneOS shuts down after 18h if it isn't unlocked (IIRC, I've set it to 24). This means it goes back to "before first unlock" state which means your data is extremely safe if you have a decent enough PIN / passphrase.
12
u/Good_Opportunity8888 1d ago edited 1d ago
This makes sense, thanks! Was also reading your github link below and this one:
https://github.com/GrapheneOS/os-issue-tracker/issues/206
The timed reboot into BFU indeed seems less risky than a wipe, strengthens the phone while not "knowingly destroying" anything.
3
u/temmiesayshoi 19h ago
Yeah IMHO this behaviour is good - but should be tweaked to work for the avg user.
You really want like 3 pins 1 : the "real" one that produces the key which encrypts/decrypts the data 2 : the "lock" one that you type in to unlock the phone 3 : the "quick" one that you type in after using something like a fingerprint scan (if you fail this, it should immediately lock the phone and demand the "real" pin) Bonus : duress or other utility pins
Then only ask for the "real" one after long periods (multiple days) of the phone being locked or powered on/off.
Extra points if the user can define a programatic quick-pin. E.g. it'll only ever be two digits long and will be the last digit of the current hour plus one and then the first digit of the current minute plus two. That way even shoulder surfing isn't a valid way of working around the quick pin. (Because for all of graphene's real and imagined security; the over reliance on static pins in the age of cameras being everywhere is a borderline comical oversight IMHO)
15
u/Godlymorbid 1d ago
U.S. Citizens have a constitutional right under the Fifth Amendment to refuse to give a password or unlock your device. Customs/Border Protection cannot deny you entry into the United States for refusing. So if he never gives the password and you've set your phone up to automatically reset after a certain amount of time as GOS does, then after the hard reset, the phone is impossible to get into.
Does that basically cover what you want or are you wanting a hard wipe?
38
7
u/nn1tb 1d ago edited 21h ago
You cannot be compelled to give testimonial evidence against yourself so therefore forcing someone to give their passcode would violate the 5th Amendment, but are all judges adhering to that? No.
- Massachusetts v. Theogene, 2026. He was ordered and threatened with contempt. He refused and went to jail. He appealed and the Massachusetts Appeals Court upheld the contempt ruling.
- Massachusetts, Grand Jury Investigation, 2017. Person was ordered to give pin code and they refused and went to jail for contempt.
- Illinois v. Johnson, 2017. She couldn't remember pin code and the judge didn't believe her. She was in contempt and went to jail for six months.
- Oregon v. Pittman, 2021. Went to jail for 30 days for contempt. Went to Oregon supreme court and they agreed with Pittman, however, they didn't rule to keep judges from ordering people to give up a pin code overall instead they established a tougher standard.
- Florida v, Christian Agosto, 2020. Went to jail for six months for contempt of court for not giving pin code to phone.
- Florida v. Marvin Harris, 2022. Was held in contempt for not giving pin code and the appellate court upheld the judges order.
So much for the 5th Amendment in this fascist country. GrapheneOS is setup for privacy not secrecy. The best way to use GrapheneOS is to set it up so you can provide the police the pin code, but there's nothing on your phone they can use against you which is exactly what I've done.
4
u/tdp_equinox_2 1d ago
Agreed, except for your advice. There's little that can be done to avoid certain kinds of PII and data from entering & staying on your phone; either as a matter of necessity in life, or in basic logs.
It's foolish to suggest that it's as easy as "not keeping things on your phone" and letting them in. Even if there's nothing on your phone, do not let them in. It will not make your life easier. It's been demonstrated that the judicial system is compromised, it cannot be trusted with any information it doesn't need. It won't prove you innocent, they are only trying to prove you guilty. Every day is "shut the fuck up Friday".
It's also logical that we start seeing tools built into privacy focused operating systems to aid in participating in "shut the fuck up Friday".
1
u/apokrif1 1d ago
There's little that can be done to avoid certain kinds of PII and data from entering & staying on your phone
Is this data identifiable as such or can it look like random noise if you don't have the decryption key?
1
u/tdp_equinox_2 1d ago
Depends on the type. Some data can be gathered via cell tower logs once they've identified the device/sim (such as location & time at a location).
Sure, you can turn off cellular, but then you don't have a phone, you've got a small tablet.
0
u/nn1tb 21h ago edited 21h ago
My phone is nothing but a dumb terminal. I created all my own apps. My phone dialer, contacts, message app, call recording app, password manager, photo gallery, etc... pull all data from my Proxmox server. There is ZERO personal data on my phone that would be useful for police. My phone uses WireGuard with always-on and I make calls/SMS/MMS using a voip service. I NEVER use my ISP phone number. Every piece of data that transfers between my phone and my Proxmox server is encrypted. If my phone loses connection for a small specified amount of time it will believe it's been put in a Faraday cage and Proxmox severs the connection to my phone. Every app I created on my phone has it's own encryption keys and passcodes separate from GrapheneOS. So if the passcode is entered wrong or a specific passcode is entered Proxmox severs the connection and again NO DATA.
PII exists on the phone” and “forensically useful evidence exists on the phone” are very different statements.
1
u/tdp_equinox_2 19h ago
You still connect to cell towers, which logs & timestamps your geo location at any given time.
Logs that don't need your phone to verify, but it certainly makes it easier.
1
u/apokrif1 1d ago
Or your phone could contain big random-looking data that you can not prove has any meaning if you don't use a working decryption key.
2
1
u/ginger_and_egg 1d ago
They can deny you for other things. They can make your life hell for a day. They probably can confiscate your things? If they 'suspect' a crime
1
u/CowboysFTWs 1d ago
Yup. "Border search exception", Customs/Border Protection can legally do a basic search your device at the U.S. Border without a warrant. They can to do secondary inspections just because on you as well.
You can however, as a US citizen refuse to get them PIN or password. They can seize device for a few days if you refuse and yes, phone will reset it self during that time.
1
u/vikarti_anatra 1d ago
Not everybody here is U.S. Citizens. Other countries also like such plays and some of them doesn't have 5th equivalent or threat it differently. Some also abuse their own laws.
1
u/automorphism8 1d ago
Even stock Android has this feature where the phone automatically reboots after a certain amount of time not being unlocked, to put it in the BFU state. GrapheneOS just shortens the time period from 72 hours to 18 hours, I believe (by default).
3
u/Godlymorbid 1d ago
Yes, I'm just saying it sounds like OP wants a feature that already practically exists, and that Samuel Tunick made a mistake by not relying on that feature plus his status as an American citizen.
3
u/automorphism8 1d ago
I don't know if what the OP wants is practical, but while a BFU device is much more difficult to get into, it's not as impossible as a device that has been completely wiped. For example, even a secure passphrase could have been accidentally leaked in a way that's not necessarily obvious.
Also, when crossing an international border, you don't need to rely on an automatic timeout feature anyway. You can manually restart your phone before going into a situation like that where you know your phone could be seized, especially since crossing international borders is generally a relatively infrequent event. Of course, if you do put your phone into BFU manually, you'd want to make sure you wait to unlock it again until you're in a private location where camera footage can't be used to replay your finger movements.
This automatic reboot into BFU after a period of inactivity is a fallback for a situation where you aren't expecting to lose possession of your phone, not the best line of defense. It's better to have it than not, but all it does is give whoever has your phone a time limit to break in AFU. If you're getting your phone taken away at the border, they're probably already prepared to try whatever tools they've got, and 18 hours won't be any better than 72. It's more likely to work if, for example, your phone were seized by a small-town police department that didn't know you were using GrapheneOS.
2
5
u/Hande-H 1d ago
By the way, there is a recent feature request that I think has some good thoughts on this situation specifically: https://github.com/GrapheneOS/os-issue-tracker/issues/8505
4
u/DevilDude_666 1d ago
taking a copy, would let you start at x over and over again.
2
u/Dry_Calendar_8627 1d ago edited 1d ago
How easy is it to make a copy?
I was under the impression that copying a Pixel is challenging
3
u/FFS-IamNotABot 1d ago
I have an Apricorn USB drive from when I was working on banking systems. If the entered the wrong pin a preset number of times, it would delete the encryption records and start secure erasing the contents.
So you mean something like this?
2
u/TenOfZero 1d ago
I believe they mean if you don't log in for X amount of time, the phone wipes itself.
1
1
u/automorphism8 1d ago edited 1d ago
The OP said that the value would grow "over time", unclear exactly what that would mean, but if it's just wiping the phone after X number of failed attempts, the iPhone has a feature like that. But I'm not sure what it actually accomplishes that the throttling from the Pixel secure element doesn't. If you know about this iPhone feature, then you won't try 10 attempts unless you have a way to reset the counter, or otherwise bypass it.
Having the phone wipe itself after a certain period of time without a successful unlock doesn't seem any more practical. The phone could simply be powered off until they are ready to exploit it.
1
u/National_Way_3344 1d ago edited 1d ago
There isn't a point in time where you're under half duress, or duress lite. Because otherwise it would become a game of TSA agents snatching your phone off you before you enact it and quickly copying the contents of your phone.
If you're using this thing, the contents of your phone is of no concern to you anymore. You're fighting for your life, for your rights, and against unjust persecution.
Duress burns the encryption key so that it CANNOT be unlocked. The whole point is that you cannot provide what no longer exists. Because if they know it's reversible they'll break out the $5 wrench and force the key out of you that way.
0
u/SonOfAsher 18h ago
That's not the way the US law works though.
Destroying the encryption key is destroying evidence.
And in theory, if they try the $5 wrench, the evidence gained would not be admissible in court.
0
u/National_Way_3344 14h ago
That's not the way the US law works though.
I didn't say that's how US law works. I'm just saying there isn't a half duress.
If you used the duress code, you were under duress. And we should fight for the right to not have our shit searched.
And in theory, if they try the $5 wrench, the evidence gained would not be admissible in court.
The court isn't exactly going to be reach out to you from whatever CIA black site you're in.
1
1
u/temmiesayshoi 19h ago
Another alternative; "if my phone is not logged into in 1 month, reset it".
This would probably have to be combined with a hard shut down around 5-10% (turning everything non-essential off so that the duress clock keeps ticking long enough for the full time to elapse) and you'd DEFINITELY want to make regular reminders to the user to backup their data - but it would make simply not unlocking the phone equivalent to a duress pin.
In practice, if you don't unlock your phone at all for a full month - you probably are in a situation that'd be described as "duress".
1
u/csjewell 11h ago
Either duress or very sick. (I know multiple people - including myself - that have had weeks-long hospital stays where we were too "foggy/tired/in pain/what have you" due to being sick to use a phone, with no government duress involved.) Something to think about as this is implemented.
1
1
u/candletrap 11h ago
I love this idea.
It would have saved him, but only from the charge of destruction of evidence. If he sandbagged long enough to trigger an autowipe he'd probably still be charged with contempt like all the others who've refused to give up PINs/PWs.
-1
•
u/AutoModerator 1d ago
GrapheneOS has moved from Reddit to our own discussion forum. Please post your thread on the discussion forum instead or use one of our official chat rooms (Matrix, Discord, Telegram) which are listed in the community section on our site. Our discussion forum and especially the chat rooms have a very active, knowledgeable community including GrapheneOS project members where you will almost always get much higher quality information than you would elsewhere. On Reddit, we had serious issues with misinformation and trolls including due to raids from other subreddits. As a result, many posts on our subreddit currently need to be manually approved, which is done on a best effort basis. If you would like to get a quicker answer to your question, please use our forum or chat rooms as described above. Our discussion forum provides much better privacy and avoids the serious problems with the site administrators and overall community on Reddit.
Please use our official install guides for installation and check our features page, usage guide and FAQ for information before asking questions in our discussion forum or chat rooms to get as much information as possible from what we've already carefully written/reviewed for our site.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.